CSIRT Contact Person and NIS2 Obligations: Legislative Decree 138/2024

Referente CSIRT e obblighi NIS2 Decreto Legislativo 138 2024

The institutionalization of the CSIRT Contact Person stems from the need to ensure operational resilience for public and private entities considered critical under the NIS2 Directive and its national transposition via Legislative Decree 138/2024. This is not a mere bureaucratic requirement, but an official technical-operational point of contact between organizations and CSIRT Italia, within the scope of the National Cybersecurity Agency (ACN).

Regulatory context and implementing acts

The CSIRT Contact Person was introduced by Legislative Decree no. 138 of September 4, 2024, in effect since October 16, 2024, which transposes Directive (EU) 2022/2555 (NIS2). It concerns entities defined as “essential” and “important,” imposing specific security and notification obligations.

  • ACN Determination no. 250916/2025 (September 19, 2025): defines the procedure for designating the CSIRT Contact Person.
  • ACN Determination no. 333017/2025: updates the regulations regarding the Contact Person and their substitutes.
  • ACN Determination no. 164179/2025: establishes the criteria for defining a “significant incident” and the IS-1, IS-2, IS-3, and IS-4 categories subject to notification.

The deadline for the appointment is December 31, 2025.

Profile and requirements of the CSIRT Contact Person

The CSIRT Contact Person must be a natural person, not a structure or company. They must be identified by name, surname, tax code, and e-mail address. The appointment is not effective until the person completes the registration personally via SPID or CIE on the ACN Services Portal.

Minimum required skills

  • Cybersecurity: understanding of digital threats.
  • Incident management: operational experience in handling digital crises.
  • Knowledge of the organization: mastery of information systems, network architectures, and digital infrastructures of the entity for which they operate.

The contact person must be able to analyze logs, interact with monitoring systems, and evaluate the significance of events according to Art. 25 of the decree.

Appointment and operational procedures

The appointment must take place between November 20 and December 31, 2025, and is divided into two phases:

  1. The Point of Contact (PdC) enters the contact person’s data on the ACN portal.
  2. The contact person accesses the portal personally to complete the registration.

In the absence of this second phase, the designation remains ineffective under the law.

Operational duties of the CSIRT Contact Person

The CSIRT Contact Person acts as a technical and organizational focal point for managing cyber incidents.

  • Detection and analysis of anomalies and technical validation of reports.
  • Internal coordination between the IT department, CISO, legal department, DPO, and corporate management.
  • Technical communications and submission of mandatory notifications to CSIRT Italia.

This ensures timely and authoritative information flow to the national authority during times of crisis.

Notification management

  1. Pre-notification within 24 hours: initial report with details on the nature and any cross-border impact.
  2. Notification within 72 hours: update with an assessment of severity, impact, and indicators of compromise (IoC).
  3. Final report within 1 month: details on causes, mitigation measures taken, and overall impact.

The contact person may also handle voluntary notifications regarding threats or near-misses according to Art. 26, without additional burdens for the reporting party.

Point of Contact and CSIRT Contact Person: differences

  • Point of Contact (PdC) – Institutional management role: handles registration, data updates, and receives official communications. Always internal to the organization.
  • CSIRT Contact Person – Technical operational role: manages incidents, sends technical notifications, and interacts with CSIRT Italia. Can be internal or external.

In smaller organizations, the two roles may coincide, while still keeping the functions distinct in internal procedures.

Delegations, substitutes, and responsibilities

The designation of the CSIRT Contact Person constitutes an operational and functional delegation for managing notifications. Material execution is the task of the contact person, while the final legal responsibility for security measures and NIS2 obligations remains with the administrative and management bodies, as provided by Art. 23 of the decree.

It is possible to appoint one or more substitutes, with the same technical requirements and the obligation to personally complete the registration. Failure to appoint substitutes may compromise 24/7 availability and operational continuity.

Consequences of failure to designate

  • Administrative sanctions according to Art. 38 of Legislative Decree 138/2024.
  • Inability to manage mandatory notifications from January 1, 2026.
  • Reputational damage and exposure to inspections by the ACN.

The CSIRT Contact Person represents the central operational figure for corporate cybersecurity within the NIS2 framework: they act as a bridge between technicians, management, and the national authority, ensuring continuity, timeliness, and quality in the management of cyber incidents.

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!